Microsoft
Software
Hardware
Network
Question : How do i permanently remove searchexe?
My PC recently contracted the pesky searchexe toolbar, passthrough homepage and all that goes with it. Using hijack this I managed to remove the toolbar, but the homepage and pop up return every time I go online after restarting my PC, as does the log entry:
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://searchexe.com/passt
hrough/ind
ex.html?
http://www.euro.dell.com/c
ountries/u
k/enu/gen/
default.ht
m
this recurs regardless of how many times i delete it. Clearly something is causing my system to revert to searchexe after every reboot - here is my logfile, can anybody suggest what I need to remove?
Logfile of HijackThis v1.97.7
Scan saved at 12:46:32, on 12/04/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\LEXBCE
S.EXE
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXPPS
.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.
exe
C:\WINDOWS\System32\DSentr
y.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\WINDOWS\System32\bcmwlt
ry.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\program files\altnet\points manager\points manager.exe
C:\Program Files\Kazaa Lite K++\KazaaLite.kpp
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\ahead\InCD\InCD.exe
C:\PROGRA~1\amok bait camp\site proc.exe
C:\Program Files\ProductsFoundry\Adve
rtisingCle
aner\advcl
eaner.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Yahoo!\Messenger\ypa
ger.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\PROGRA~1\Altnet\DOWNLO~
1\asm.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Daniel Calder\My Documents\Hijack This\HijackThis.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://searchexe.com/passt
hrough/ind
ex.html?ht
tp://
www.e
uro.dell.c
om/countri
es/uk/enu/
gen/defaul
t.htm
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtr
ay.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.
exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentr
y.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [bcmwltry] bcmwltry.exe
O4 - HKLM\..\Run: [removecpl] RemoveCpl.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [KAZAA] "C:\Program Files\Kazaa Lite K++\kpp.exe" "C:\Program Files\Kazaa Lite K++\KazaaLite.kpp" /SYSTRAY
O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCh
eck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [slowbend] C:\PROGRA~1\amok bait camp\site proc.exe
O4 - HKLM\..\Run: [AdvertisingCleaner] C:\Program Files\ProductsFoundry\Adve
rtisingCle
aner\advcl
eaner.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypa
ger.exe -quiet
O4 - Startup: Check For Dope Wars Updates.lnk = C:\Program Files\Dopewars\WiseUpdt.ex
e
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: AOL 8.0 Tray Icon.lnk = C:\Program Files\AOL 8.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {2F0D1DA3-F3E4-4C67-BB5C-5
AFD70C1A4A
5} (UDConnect Class) -
http://01.sharedsource.org
/html/UDCo
nn.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-F
A1D4F56A2A
B} (YInstStarter Class) -
http://download.yahoo.com/
dl/install
s/yinst030
9.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5
D2C442ADFD
E} -
http://a1540.g.akamai.net/
7/1540/52/
20030530/
q
tinstall.i
nfo.apple.
com/abarth
/us/win/
Qu
ickTimeIns
taller.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://active.macromedia.c
om/flash2/
cabs/swfla
sh.cab
O17 - HKLM\System\CCS\Services\T
cpip\..\{E
28AC518-9F
F0-4448-A1
5A-613BB32
71192}: NameServer = 194.168.4.100 194.168.8.100
Answer : How do i permanently remove searchexe?
Remove search.exe
http://www.pestpatrol.com/
PestInfo/s
/search-
ex
e.asp#Dete
ction%20an
d%20Remova
l
Random Solutions
Creating an ODBC connection via VBA utilizing a generic username and password
Folder Contents
Recipe Database
Priniting report causes error "2212 couldn't print object"
No record of File Replication System, SYSVOL started - DCDIAG Errors
Python: how to check mail status
Ms Access Inserting/Updating Data using Forms.
Importing a .pst into a public folder, I can see all the contents, other users only see "Deleted Items" folder.
Vue 5 Infinite tutorials
Configure directory on linux server to block access to public, but allow access from web application.